WorkOS Logo

WorkOS

GRC Engineer

Reposted Yesterday
Remote
Hiring Remotely in United States
175K-275K Annually
Senior level
Remote
Hiring Remotely in United States
175K-275K Annually
Senior level
The GRC Engineer will lead WorkOS's Governance, Risk, and Compliance program, ensuring compliance frameworks are applied and automated. Responsibilities include managing compliance, risk, and customer audits, and collaborating with various teams to build durable systems for compliance processes.
The summary above was generated by AI

About WorkOS 🚀

WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations.
We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Vercel, and Plaid.
As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control—helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.

About the Security Team

The Security team at WorkOS is responsible for keeping the data and identities of hundreds of millions of users secure. Security is fundamental to our products, and customer trust is the foundation of our success.

We are a highly collaborative group with a strong technical mindset. Our security program is shaped by hands-on experience attacking and defending systems, and applying lessons from across the industry. We embrace the latest advancements in practices and tooling that make modern security teams effective.

Today, our team spans product security, cloud security, and detection & response. We are expanding our internal GRC function to scale our compliance, risk, and customer trust programs as we grow.

About the Role

We are looking for a GRC Engineer to lead and own our Governance, Risk, and Compliance program.

WorkOS has foundational compliance in place; SOC 2, HIPAA, GDPR, PCI-DSS SAQ D, and a growing set of customer and regulatory obligations. What we are looking for now is a leader for our compliance function: someone who can build on the trust our enterprise customers have placed in us, own our existing frameworks, and drive us into the next tier of certifications.

You will work with security leadership to navigate our GRC program. You will help set the strategy, shape the roadmap, and build the systems and culture that make compliance a byproduct of how we build software.

This is a remote or hybrid position, open to candidates based in Canada or the United States.

What You'll Do
  • Own our compliance function. Frameworks, policies, controls, and audits are yours. Make compliance part of how we build and ship, not a separate track.

  • Build the GRC culture. Own security awareness, internal education, and the cross-functional work that makes compliance a shared responsibility across the company.

  • Lead our next certifications. Drive readiness and on-going compliance for future frameworks like ISO 27001, EU-US DPF, FedRAMP; scoping the controls, documentation, and collaborating across the organization to make it happen.

  • Partner directly with customers. Be the voice of our compliance program to our customers. Support audits, enable sales on compliance-gated deals, and build on the trust we've established with the companies that depend on us.

  • Own risk across WorkOS. Run our risk and third-party risk programs. Identify risks as they emerge, drive remediation, and surface signal to leadership.

  • Scale through automation. Reduce manual toil wherever it hides. Design processes, tooling, and AI-assisted workflows so the compliance function scales without scaling headcount.

Who You Are
  • A trusted advisor, internally and externally. You work fluidly with customers, engineering, legal, sales, and auditors. You can explain a control, defend a design decision, manage a difficult customer conversation, and communicate clearly, in writing.

  • A pragmatic, forward-thinker. You spot audit tight spots before they arrive, have the experience to work through them, and how to future-proof against them. You reason systematically about real-world impact, and ensure we reduce risk over checking boxes.

  • A strong partner to engineering. You build trust by understanding engineers' priorities and making the compliant path the easiest path. You act as the bridge between auditor asks and engineering work with the ability to translate between the two.

  • Framework-fluent. You have hands-on experience implementing and auditing SOC 2 and other major frameworks (ISO 27001, PCI DSS, NIST 800-53, FedRAMP), and you can reason about new frameworks from first principles.

  • A builder, not just an operator. You see manual, repetitive GRC work as tech debt and look for ways to design it away: through process, tooling, AI, or partnering with engineering to build what's needed. You are not looking for a role where you chase screenshots and manage spreadsheets.

Qualifications
  • 5+ years in a GRC or compliance role, with demonstrated ownership of cross-functional compliance projects, from scoping through delivery, at a cloud-native company.

  • Hands-on experience implementing or auditing SOC 2 plus one other major framework (ISO 27001, PCI DSS, NIST 800-53).

  • Experience building or significantly maturing a GRC function at a high-growth company; you have seen the zero-to-one arc, not just maintained a mature program.

  • Experience with GRC automation platforms (Vanta, Drata, or similar); migrating into, configuring, and building in them.

  • Strong written and verbal communication, particularly customer-facing advisory: explaining controls, handling objections, and managing audit and enterprise-deal conversations.

Bonus:

  • Privacy regulations (GDPR, CCPA, HIPAA) and PII classification; we have employees and customers across multiple jurisdictions.

  • FedRAMP experience as implementer or auditor.

  • Proficiency in a programming or scripting language (Python, TypeScript, Go, or similar); you can read code, write automation, and leverage AI in day-to-day work.

  • GRC-as-code / compliance-as-code practices; version-controlled policies, automated control testing, or CI-integrated evidence collection.

  • Familiarity with authentication and identity (SAML, OIDC, SCIM); highly relevant given our product.

Benefits and Perks (US Only) 💖

At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.

 

Benefits include:

- Competitive pay

- Substantial equity grants

- Healthcare insurance (Medical, Dental and Vision) for you and your family

- 401k matching

- Wellness and fitness monthly allowances

- PTO + paid holidays + unlimited sick leave

- Unlimited token usage

Please inquire directly with our recruiting team for benefits available to those working outside the US.

 

Equal Opportunity Employer

WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Similar Jobs

13 Days Ago
Remote
Senior level
Senior level
Software
As a Senior Software Engineer at Vanta, you will lead projects, set technical direction, develop product functionality, and mentor engineers, leveraging modern frameworks like TypeScript, React, and Node.js.
Top Skills: Node.jsReactTypescript
6 Hours Ago
Remote
142K-227K Annually
Senior level
142K-227K Annually
Senior level
Cloud • Fintech • Food • Information Technology • Software • Hospitality
As a Staff Software Engineer, you'll lead a team in developing and delivering scalable software solutions for employee management in the restaurant industry, focusing on enhancing customer and employee experiences.
Top Skills: GraphQLJavaKotlinReactRestTypescript
6 Hours Ago
In-Office or Remote
129K-206K Annually
Senior level
129K-206K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
As a Strategic Sales Engineer, you'll provide technical direction, support sales efforts, and develop integrated solutions addressing customer needs to exceed sales quotas.
Top Skills: Backup And Disaster RecoveryCloud Data ManagementData AnalyticsSan (Storage Area Network) Systems

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account